ads.installads.com

Temp Organization

Domain Information

The domain ads.installads.com registered by Temp Organization was initially registered in July of 2015 through NICS TELEKOMUNIKASYON TICARET LTD.STI.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Istanbul, Istanbul within Turkey which resides on the RIPE Network Coordination Centre network.
Registrar:
NICS TELEKOMUNIKASYON TICARET LTD.STI.

Server location:
Istanbul, Turkey (TR)

Create date:
Sunday, July 26, 2015

Expires date:
Tuesday, July 26, 2016

Updated date:
Sunday, July 26, 2015

ASN:
AS29262 IDEALHOSTING IDEALHOSTING SUNUCU INTERNET HIZ. TIC. LTD STI,TR

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.MediaGet.Banner.Installer (M), PUP.MediaGet.Inbox.Installer (M)
100.00%

Bkav FE
W32.HfsAdware
20.00%

Malwarebytes
PUP.Optional.MediaGet
20.00%

ESET NOD32
Win32/MediaGet.AE potentially unwanted (variant)
20.00%

Kaspersky
not-a-virus:HEUR:Downloader.Win32.MediaGet
20.00%

Comodo Security
Application.Win32.MediaGet.G
20.00%

Dr.Web
Program.MediaGet.133
20.00%

Sophos
MediaGet (PUA)
20.00%

G Data
Win32.Adware.MediaGet
20.00%

IKARUS anti.virus
PUA.MediaGet
20.00%

AVG
Banne
20.00%

Baidu Antivirus
Adware.Win32.MediaGet
20.00%

Qihoo 360 Security
Win32/Virus.e7d
20.00%

The domain ads.installads.com has been seen to resolve to the following IP address.

mail168164.dergireklam.com
April 20, 2016

File downloads found at URLs served by ads.installads.com.

1 / 68      (PUP)

13 / 68    (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)
http://ads.installads.com/indir.php?&t1=1080p&is=Buz Devri 4:  (outlast-full-turkce-indir_id2959289ids2s.exe)

13 / 68    (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

13 / 68    (PUP)

The following 2 files have been seen to comunicate with ads.installads.com in live environments.

URL:
http://ads.installads.com/

Title:
“installads”

Web server:
Apache